Windows Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOperating SystemsWindows Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old May 8th, 2003, 01:00 PM
Black Vivi Black Vivi is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 23 Black Vivi User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
big prob

I recently had a virus called AyerHS/Yaha, I just got rid of it today using Stinger, but now a load of other files are missing, and files that are meant to load on startup aren't working either...

Reply With Quote
  #2  
Old May 8th, 2003, 02:27 PM
PartieHonteuse PartieHonteuse is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2003
Location: Kzoo, Michigan
Posts: 37 PartieHonteuse User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to PartieHonteuse Send a message via Yahoo to PartieHonteuse
well..

It could be that this "Stinger" program saw those files as infected and either wiped them out or "fixed" them which actuall ruined them..........another possibility is that this program didn't find every last bit of Yaha
__________________
"I dislike duals. If a man were to challenege me to a dual, i'd lead him lovingly and forgivingly to a quiet place, and kill him" ~Mark Twain

Reply With Quote
  #3  
Old May 9th, 2003, 01:27 AM
Black Vivi Black Vivi is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 23 Black Vivi User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Stinger said it only deleted the 3 files from the yaha virus, so it couldn't be that...

but this is really annoying, it won't let apache run...

Reply With Quote
  #4  
Old May 9th, 2003, 04:01 AM
PartieHonteuse PartieHonteuse is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2003
Location: Kzoo, Michigan
Posts: 37 PartieHonteuse User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to PartieHonteuse Send a message via Yahoo to PartieHonteuse
A couple more options for you if you haven't already tried these is to use some other removal tool to make sure "Stinger" got evertyhing. I've never heard of nor used Stinger but that doesn't mean it doesn't work but it's always a good bet to try a couple of other methods. Another method that I would recommend is the removal tool from BitDefender. It's the removal tool for Win32.Yaha.(A-Q), I'm not sure if this removal tool and your "variant" of the virus are the same but it's worth giving it a shot. If that's doesn't work for you open regedit (start menu, run, type "regedit" without quotes, hit ok) and go to this location like you are using Windows Explorer...

HKEY_Classes_Root\exefile\shell\open\command

once you click the "command" key on the right pane you should see a "default" and a value of "%1" %*. If the value for "default" key says C:\Recycled\%%%%.exe %1 %* where %%%%= a random string then you are still infected. you need to replace it to read "%1" %* (as it is shown).

If neither the removal tool that I suggested or another of the ones you found do not work nor if the registry key is changed the only other option that I have in mind is to backup, reformat, reinstall. Or wait for someone to come along that is smater than me. (i'd go with wait for someone to come along that is smarter than me lol) I hope this helped a little bit....

Link to BitDefender removal tool.....

http://www.bitdefender.com/download...e=AntiYahaa.exe


Good luck!
Mike

Reply With Quote
  #5  
Old May 9th, 2003, 11:13 AM
Black Vivi Black Vivi is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 23 Black Vivi User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
regedit, windows explorer and bitdefender won't open

i found a way to make msn open, which is go on hotmail, so if anyone knows how to write a javascript file that wud open the file automatically for me, hopefully that'd work...

Reply With Quote
  #6  
Old May 9th, 2003, 04:27 PM
PartieHonteuse PartieHonteuse is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2003
Location: Kzoo, Michigan
Posts: 37 PartieHonteuse User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to PartieHonteuse Send a message via Yahoo to PartieHonteuse
http://housecall.antivirus.com/start_corp.asp


it's a free online virus scanner....don't know if it has Removal capabilities for the virus, but good luck....

oh and try restarting your computer in safe mode.. and running bitdefender and regedit...ya never know

Reply With Quote
  #7  
Old May 9th, 2003, 04:34 PM
Black Vivi Black Vivi is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 23 Black Vivi User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
nvm, i fixed it

Reply With Quote
  #8  
Old May 9th, 2003, 06:09 PM
PartieHonteuse PartieHonteuse is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2003
Location: Kzoo, Michigan
Posts: 37 PartieHonteuse User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to PartieHonteuse Send a message via Yahoo to PartieHonteuse
i'm curious as to how :-D if you don't mind

Reply With Quote
  #9  
Old May 9th, 2003, 06:24 PM
Black Vivi Black Vivi is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 23 Black Vivi User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
i used a tool called FixYaha

Reply With Quote
  #10  
Old July 11th, 2003, 11:54 AM
antares antares is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: Saudi Arabia (but i not saudi, i asian)
Posts: 6 antares User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
I have the ayerhs virus too. I used fixyaha but still my drive C is infected. I only saw one thing that the tool fixed. You guys know any other online virus checkers? Can you post the links. I dun like to try stinger... thanks in advance

Reply With Quote
  #11  
Old July 11th, 2003, 03:11 PM
Black Vivi Black Vivi is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2003
Posts: 23 Black Vivi User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
fixyaha isn't an online tool

Reply With Quote
  #12  
Old July 12th, 2003, 09:58 AM
antares antares is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: Saudi Arabia (but i not saudi, i asian)
Posts: 6 antares User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
I know. I downloaded it. I need other tools; online or not. HELP!

Reply With Quote
  #13  
Old July 12th, 2003, 08:20 PM
PartieHonteuse PartieHonteuse is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2003
Location: Kzoo, Michigan
Posts: 37 PartieHonteuse User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
Send a message via AIM to PartieHonteuse Send a message via Yahoo to PartieHonteuse
a couple of questions for you antares.

1. Do you have windows ME or XP installed?...if yes read 2 if no, read 3.

2. If yes...did you disable system restore before running the FixYaha removal tool?

3. Did you run the FixYaha tool in safe mode (if running windows XP)?

for question two if you have the system restore function enabled then the virus would've been saved in there also. IT's also a good idea after finding out that you have been infected with a virus to disable system restore and then renable. The reason for this is so you can clear the stored files for system restore. Also, if this is the FixYaha removal tool from Symantec (Norton) they also tell you to run the tool in safe mode.

If it is not the FixYaha from Symantec then you can try it here..

http://securityresponse.symantec.co...ter/FixYaha.com

and read about it here...

http://securityresponse.symantec.co...moval.tool.html

Last edited by PartieHonteuse : July 12th, 2003 at 08:30 PM.

Reply With Quote
  #14  
Old July 13th, 2003, 09:27 AM
antares antares is offline
Junior Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: Saudi Arabia (but i not saudi, i asian)
Posts: 6 antares User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
That's the fixyaha i tried. I disabled system restore before running the tool as well. Is it an effect of the virus not being removed soon enough? I had it for over 3 months and only found a tool to remove it the other day

Reply With Quote
  #15  
Old July 15th, 2003, 03:26 AM
Known_criminal Known_criminal is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2003
Location: Mississippi
Posts: 475 Known_criminal User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 6
virus

http://securityresponse.symantec.co....yaha.e@mm.html
that is a link to nortons fix tool for that virus, you really need a virus program that is up2date, that scans email
if you dont want to pay for one go to
http://www.grisoft.com/
download the avg free edition, it updates for freeif you system is still causing trouble, install the programs that do not work again, dont remove, if a program install offers a repair option try it, if windows it's self is causing trouble do the same, do not format, and you wont loose anything

Reply With Quote
Reply

Viewing: Dev Shed ForumsOperating SystemsWindows Help > big prob


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump